Re: OpenBSD firewall

From: phn@icke-reklam.ipsec.nu
Date: 02/08/03


From: phn@icke-reklam.ipsec.nu
Date: Sat, 8 Feb 2003 22:16:03 +0000 (UTC)

Chenghuai Lu <lulu@cc.gatech.edu> wrote:
> Does anyone know whether or not the OpenBSD firewall can prevent ICMP
> tunneling? If so, what is the mechanism it uses? If you could provide me a
> link to it, that will be great!

Any firewall (worth mentioning )can stop ICMP packets. OpenBSD has a
'pf' filter that does more then so, it can optionally "scrub" streams
to remove nasty packets.

See "http://www.openbsd.org/faq/faq6.html#PF" for hints about features.

> Thanks.

> Lu

-- 
Peter Håkanson         
        IPSec  Sverige      ( At Gothenburg Riverside )
           Sorry about my e-mail address, but i'm trying to keep spam out,
	   remove "icke-reklam" if you feel for mailing me. Thanx.


Relevant Pages

  • Re: network problems 7.0-p3: sendto: Operation not permitted
    ... I believe that fix was also just for TCP. ... This indicates a high number of ICMP packets being received. ... This is normal behaviour for a cable modem network; ...
    (freebsd-stable)
  • Re: ICMP flood - how to cure?
    ... > to the network it began to send out the ICMP packets again. ... Monitor [included with Windows] from Control Panel, ...
    (comp.security.firewalls)
  • Re: [Full-Disclosure] Transamericana.org
    ... icmp packets. ... > I've been doing some research on creating covert channels using icmp ... > packets and a bounce server and so far everything worked fine. ... > bounce server using icmp packets. ...
    (Full-Disclosure)
  • Re: DOS attacks
    ... >> There is also a method to prevent DoS attacks by limiting what port it ... you could use icmp limiting to limit icmp incoming and ... Your firewall then blocks all other ICMP packets outright for the next hour. ...
    (comp.os.linux.security)
  • Re: What can delay [comm send -async ...]?
    ... First, ping uses ICMP, which is very different from TCP. ... of ping are just an application-level timeout, since ICMP packets are ...
    (comp.lang.tcl)